CISA Alert on Linux Kernel Flaw - Spiceworks (2024)

CISA added a Linux privilege escalation vulnerability that works on kernel versions between 5.14 and 6.6.14 to its Known Exploited Vulnerabilities (KEV) catalog. Learn more about the threat and what it means for Linux users.

CISA Alert on Linux Kernel Flaw - Spiceworks (2)

(Credits: Shutterstock.com)

  • CISA has added a new security flaw affecting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog.
  • The vulnerability, CVE-2024-1086, allows attackers to elevate their privileges, even allowing the execution of random code.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new security vulnerability to its KEV catalog that impacts Linux kernel versions between 5.14 and 6.6.14. Designated CVE-2024-1086, the issue is mentioned as a CVSS score: 7.8 high severity bug that exploits the netfilter component to allow a local attacker to escalate privileges up to the root level, potentially enabling the execution of arbitrary code.

The netfilter component is a Linux kernel framework that enables network operations such as port translation, packet filtering, and network address translation. CVE-2024-1086 is described as a use-after-free bug, which means that it is a flaw associated with the incorrect use of dynamic memory in the process of program operations.

See more: U.S. Government Sanctions Cybercrime Network Using Free VPN Services for Proxy Botnet

While a patch for the vulnerability has been available since January 2024, it has only now been designated as an actively exploited bug. However, while federal agencies are recommended to apply the patches by the 20th of June, 2024, CISA has not provided any details regarding the nature of the attacks exploiting this vulnerability.

CISA added another vulnerability, CVE-2024-24919, which impacts Check Point network gateway security products, to its KEV catalog. This vulnerability allows attackers to read data on gateways that are mobile access enabled or have a remote access VPN. Threat actors have reportedly used it to breach corporate networks and access remote firewalls.

Considering that the Linux kernel bug affects distributions such as Ubuntu, Debian, Fedora, and Red Hat, the alert from CISA highlights the need for prompt patching efforts for individuals and organizations running Linux systems.

LATEST NEWS STORIES

CISA Alert on Linux Kernel Flaw - Spiceworks (3)

Anuj Mudaliar is a content development professional with a keen interest in emerging technologies, particularly advances in AI. As a tech editor for Spiceworks, Anuj covers many topics, including cloud, cybersecurity, emerging tech innovation, AI, and hardware. When not at work, he spends his time outdoors - trekking, camping, and stargazing. He is also interested in cooking and experiencing cuisine from around the world.

CISA Alert on Linux Kernel Flaw - Spiceworks (4)

Do you still have questions? Head over to the Spiceworks Community to find answers.

CISA Alert on Linux Kernel Flaw - Spiceworks (2024)
Top Articles
Digital Textile Printing Market Trend, Share & Forecast 2033
8 Types of Americans Who Aren’t Eligible to Get Social Security
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Doby's Funeral Home Obituaries
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Jonah Leffler

Last Updated:

Views: 5349

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.